Cross-source coverage

T1110 / ATT&CK

Brute Force

327 rules · 324 families across 9 sources.

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained. Without knowledge of the password for an account or set of accounts, an adversary may systematically guess the password using a repetitive or iterative mechanism. Brute forcing passwords can take place via interaction with a service that will check the validity of those credentials or offline against previously acquired credential data, such as password hashes.

Brute forcing credentials may take place at various points during a breach. For example, adversaries may attempt to brute force access to Valid Accounts within a victim environment leveraging knowledge gathered from other post-compromise behaviors such as OS Credential Dumping, Account Discovery, or Password Policy Discovery. Adversaries may also combine brute forcing activity with behaviors such as External Remote Services as part of Initial Access.

If an adversary guesses the correct password but fails to login to a compromised account due to location-based conditional access policies, they may change their infrastructure until they match the victim’s location and therefore bypass those policies.

Platforms
Containers · ESXi · IaaS · Identity Provider · Linux · macOS · Network Devices · Office Suite · SaaS · Windows
Telemetry
WinEventLog:Securityauditd:USER_LOGINazure:signinlogsmacos:unifiedlogm365:unified

How MITRE says to detect it DET0463

Brute Force Authentication Failures with Multi-Platform Log Correlation

Windows Analytic 1275

High volume of failed logon attempts followed by a successful one from a suspicious user, host, or timeframe

  • WinEventLog:Security EventCode=4776, 4625

Linux Analytic 1276

Multiple authentication failures for valid or invalid users followed by success from same IP/user

  • auditd:USER_LOGIN USER_AUTH

Identity Provider Analytic 1277

Password spraying or brute force attempts across user pool within short time intervals

  • azure:signinlogs Sign-in logs

macOS Analytic 1278

Multiple failed authentications in unified logs (e.g., loginwindow or sshd)

  • macos:unifiedlog auth

SaaS Analytic 1279

Excessive login attempts followed by success from SaaS apps like O365, Dropbox, etc.

  • m365:unified Sign-in logs

Sub-techniques with coverage

Counted in the 327 above — a rule tagged a sub-technique covers this technique too.


Wazuh Core Ruleset

97 rules · 94 families
Detection Severity Format
Apache: Multiple authentication failures with invalid user. High Wazuh XML
ASA: Multiple AAA (VPN) authentication failures. High Wazuh XML
Asterisk: Multiple failed logins. 2 variants High Wazuh XML
Asterisk: Multiple failed logins. 2 variants High Wazuh XML
AWS Cloudtrail: - - Possible break in attempt (high number of login attempts). · rule 80255 High Wazuh XML
AWS S3 multiple authentication failures. High Wazuh XML
by a success. High Wazuh XML
CiscoVPN: Multiple VPN authentication failures. High Wazuh XML
Courier brute force (multiple failed logins). High Wazuh XML
Courier: Multiple connection attempts from same source. High Wazuh XML

+ 87 more from Wazuh Core Ruleset → showing the 10 highest-severity

splunk/security_content

72 rules
Detection Severity Format
ASL AWS Credential Access GetPasswordData Undefined SPL
ASL AWS Credential Access RDS Password reset Undefined SPL
ASL AWS IAM Assume Role Policy Brute Force Undefined SPL
AWS Credential Access Failed Login Undefined SPL
AWS Credential Access GetPasswordData Undefined SPL
AWS Credential Access RDS Password reset Undefined SPL
AWS High Number Of Failed Authentications From Ip Undefined SPL
AWS IAM Assume Role Policy Brute Force Undefined SPL
AWS Multiple Users Failing To Authenticate From Ip Undefined SPL
AWS Unusual Number of Failed Authentications From Ip Undefined SPL

+ 62 more from splunk/security_content → showing the 10 highest-severity

elastic/detection-rules

45 rules
Detection Severity Format
AWS Management Console Brute Force of Root User Identity High Elastic TOML
Deprecated - Potential Password Spraying of Microsoft 365 User Accounts High Elastic TOML
Entra ID Excessive Account Lockouts Detected High Elastic TOML
Entra ID Protection - Risk Detection - Sign-in Risk High Elastic TOML
Entra ID Protection - Risk Detection - User Risk High Elastic TOML
Entra ID Sign-in TeamFiltration User-Agent Detected High Elastic TOML
Multiple SonicWall Login Failures Followed by Successful Login High Elastic TOML
Okta Successful Login After Credential Attack High Elastic TOML
Potential SSH Brute Force Detected on Privileged Account High Elastic TOML
Potential Successful SSH Brute Force Attack High Elastic TOML

+ 35 more from elastic/detection-rules → showing the 10 highest-severity

SigmaHQ/sigma

28 rules
Detection Severity Format
External Remote SMB Logon from Public IP High Sigma
HackTool - CrackMapExec Execution High Sigma
HackTool - Hashcat Password Cracker Execution High Sigma
HackTool - Hydra Password Bruteforce Execution High Sigma
Hack Tool User Agent High Sigma
Password Spray Activity High Sigma
Potential MFA Bypass Using Legacy Client Authentication High Sigma
Sign-in Failure Due to Conditional Access Requirements Not Met High Sigma
Use of Legacy Authentication Protocols High Sigma
Account Lockout Medium Sigma

+ 18 more from SigmaHQ/sigma → showing the 10 highest-severity

panther-labs/panther-analysis

27 rules
Detection Severity Format
Azure Excessive Account Lockouts High Panther Python
Failed Root Console Login High Panther Python
GSuite Workspace Password Reuse Has Been Enabled High Panther Python
GSuite Workspace Strong Password Enforcement Has Been Disabled High Panther Python
Netskope Many Unauthorized API Calls High Panther Python
OpenAI Brute Force Login Success High Panther Python
Admin logged out because of successive login failures Medium Panther Python
Anthropic SSO Login Failed Medium Panther Python
AppOmni Alert Passthrough Medium Panther Python
Azure Many Failed SignIns Medium Panther Python

+ 17 more from panther-labs/panther-analysis → showing the 10 highest-severity

Azure/Azure-Sentinel

25 rules
Detection Severity Format
Brute force attack against user credentials (Uses Authentication Normalization) Medium KQL
Failed AWS Console logons but success logon to AzureAD Medium KQL
Failed AzureAD logons but success logon to AWS Console Medium KQL
Failed AzureAD logons but success logon to host Medium KQL
Failed host logons but success logon to AzureAD Medium KQL
High count of failed attempts from same client IP Medium KQL
High count of failed logons by a user Medium KQL
IP with multiple failed Microsoft Entra ID logins successfully logs in to Palo Alto VPN Medium KQL
New country signIn with correct password Medium KQL
Potential Password Spray Attack (Uses Authentication Normalization) Medium KQL

+ 15 more from Azure/Azure-Sentinel → showing the 10 highest-severity

socfortress/Wazuh-Rules

15 rules
Detection Severity Format
Brute-force SSH attempt with sshpass targeting localhost (T1110.004 - Credential Stuffing) High Wazuh XML
Credential stuffing attempt using sshpass inside shell script (T1110.004) High Wazuh XML
Possible sudo brute-force detected: use of 'sudo -S whoami' High Wazuh XML
Sysmon - Event 1: Process creation · AzureAD Brute Force (T1110.001) High Wazuh XML
Sysmon - Event 1: Process creation · DomainPasswordSpray.ps1 Execution (T1110.003) High Wazuh XML
Sysmon - Event 1: Process creation · ESXi SSH Brute Force (T1110.001) High Wazuh XML
Sysmon - Event 1: Process creation · Hashcat Password Cracking (T1110.002) High Wazuh XML
Sysmon - Event 1: Process creation · Kerbrute Credential Stuffing (T1110.004) High Wazuh XML
Sysmon - Event 1: Process creation · Kerbrute Execution (T1110.001) High Wazuh XML
Sysmon - Event 1: Process creation · LDAP Brute Force PowerShell (T1110.001) High Wazuh XML

+ 5 more from socfortress/Wazuh-Rules → showing the 10 highest-severity

chronicle/detection-rules

14 rules
Detection Severity Format
aws_guardduty_brute_force_activity_detected High YARA-L
onelogin_otp_brute_force_attack High YARA-L
aws_unusual_number_of_failed_authentications_from_the_same_ip Medium YARA-L
okta_mfa_brute_force_attack Medium YARA-L
okta_threatinsight_login_failure_with_high_unknown_users Medium YARA-L
okta_threatinsight_suspected_brute_force_attack Medium YARA-L
okta_threatinsight_suspected_password_spray_attack Medium YARA-L
okta_threatinsight_targeted_brute_force_attack Medium YARA-L
okta_user_rejected_multiple_push_notifications Medium YARA-L
rw_windows_password_spray_T1110_003 Medium YARA-L

+ 4 more from chronicle/detection-rules → showing the 10 highest-severity

Bert-JanP/Hunting-Queries-Detection-Rules

4 rules
Detection Severity Format
Kerberos attacks Undefined KQL
MITRE ATT&CK Mapping Undefined KQL
Multiple Accounts Locked Undefined KQL
Password change after succesful brute force Undefined KQL

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.